Authenticator System is Flawed

Authenticator System is Flawed

in Account & Technical Support

Posted by: drenmartin.1462

drenmartin.1462

Hello fellow Tyrians!

I just had to open a support ticket earlier this week because I had to factory reset my phone. One of the precious apps on my phone is the Google Authenticator app. Any account I have online that supports 2-Factor Authentication through the Google Authenticator app, I set up immediately. Naturally, Guild Wars 2 is set up in this manner and works great!

The flaw comes in when I have to move to a new phone, have to factory reset my phone, or (knock on wood) I lose my phone.

Every other service out there that provides 2-Factor Authentication makes this a very simple process. When you enable 2-Factor, they give you anywhere from 1-10+ “Secret Codes” or “Backup Codes” in case you need to move your Authenticator App to another device. It’s pretty smooth! The only service/account that doesn’t provide this is Guild Wars 2.

Support does offer instructions that if you want to move devices, you should delink the Authenticator from your app first and then get your new device/factory reset your device. But, if you lose your phone, your authenticator app is still out there generating codes to log in while you’re waiting for Support to delink the authenticator.

My suggestion to support was to give us the Backup codes like every other service that offers 2-Factor Authentication, but this was not addressed in my support request. It was a standard canned response that was very impersonal.

TL;DR —> Guild Wars 2 doesn’t offer backup/secret codes for 2-Factor Authentication using the Google Authenticator. It creates a headache when switching devices. When will Guild Wars 2 offer this extra protection to us?

Authenticator System is Flawed

in Account & Technical Support

Posted by: Healix.5819

Healix.5819

The secret code was shown to you during the initial setup of the authenticator, both as a string and a QR image. Allowing you to see the code again is a vulnerability, which is why you’re supposed to save it in a secure location if you ever need to recreate your authenticator.

Attachments:

Authenticator System is Flawed

in Account & Technical Support

Posted by: FlamingFoxx.1305

FlamingFoxx.1305

Honestly I don’t think there’s enough emphasis on the fact that you need to save that secret code. Yes I know it says “and save it” at the top, but they should perhaps state in the description below that you’ll need the code if you ever lose or move to another device. As someone who wasn’t very well versed on Authenticators i had no idea that it might not be simple to change to a new device.